SECURITY & DATA PRACTICES
A secured facility workspace built around a no-PHI workflow.
Recovery Group Studio protects facility and facilitator accounts while deliberately keeping client names, identifiers, and completed clinical records outside the service.
Effective: September 19, 2026
1. The data boundary
Recovery Group Studio is designed for group topics, program context, facilitator preferences, generated materials, non-identifying observations, and operational scheduling. It is not designed or offered as a repository for protected health information. Users must not enter client names, initials linked to a person, dates of birth, medical-record numbers, attendance lists, diagnoses tied to a person, contact details, or completed clinical notes.
2. Account and access protections
The service uses hashed passwords, secure session cookies, email verification, one-time codes for new devices, role-based facility access, invitation controls, rate limits, and cross-origin request protections. Facility administrators manage their own members and roles. Administration-only access is separated from facilitator seats.
3. Facility separation and storage
Facility workspaces are separated by account and organization identifiers. Access-controlled application data is stored in Cloudflare infrastructure, and submitted feedback images use restricted object storage. Payment-card details are handled by Stripe and are not stored by Recovery Group Studio.
4. Encryption and network delivery
Production traffic is delivered over HTTPS with encryption in transit. Security headers restrict framing, content interpretation, browser permissions, and cross-origin authentication behavior. Cloudflare provides the application hosting, network edge, database, object storage, and AI infrastructure used by the service.
5. AI processing and linked sources
Group topics, instructions, program context, and requested source material may be processed by configured AI services to generate and review content. The no-PHI rule applies to every generation field. YouTube and other linked sources remain subject to their own services and policies. Generated materials must be reviewed by a qualified facilitator before use.
6. HIPAA, BAAs, and independent certifications
Recovery Group Studio currently relies on a no-PHI product design and does not currently offer a Business Associate Agreement. The service does not currently claim HIPAA certification, SOC 2 certification, or any other independent security certification. Facilities should keep protected information in their approved clinical systems and evaluate the service under their own privacy, security, and procurement requirements.
7. Reporting a security concern
Send suspected account compromise, unauthorized access, or other security concerns to support@recoverygroupstudio.com. Do not include passwords, one-time codes, payment-card information, client identifiers, or protected health information in the report.